ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE - elttam
https://ift.tt/Ov7RV9K
Submitted September 23, 2026 at 09:23AM by AnimalStrange
via reddit https://ift.tt/Z5FtdJp
https://ift.tt/Ov7RV9K
Submitted September 23, 2026 at 09:23AM by AnimalStrange
via reddit https://ift.tt/Z5FtdJp
Elttam
ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE - elttam
Details a pre-auth format string vulnerability in tac_plus, a popular daemon implementing TACACS+ for network device management, and the shared secret oracle that makes it a practical RCE chain.
Leaked GitHub App private keys let researchers impersonate 440 apps including CDC and BuildBuddy
https://ift.tt/jMGDAOp
Submitted September 23, 2026 at 10:50AM by mabote
via reddit https://ift.tt/ypd8Dr5
https://ift.tt/jMGDAOp
Submitted September 23, 2026 at 10:50AM by mabote
via reddit https://ift.tt/ypd8Dr5
GitGuardian Blog - Take Control of Your Secrets Security
GitHub App Private Keys: 474 Leaked Keys Still Work
GitGuardian tested thousands of leaked GitHub App private keys and found 474 valid ones, some with admin access to entire organizations. CDC and BuildBuddy were among those affected. See the findings.
Free, hands-on 14-week university security course (open to anyone online)
https://ift.tt/HzjLWeV
Submitted September 22, 2026 at 03:16PM by mrigaki
via reddit https://ift.tt/I6kRGyN
https://ift.tt/HzjLWeV
Submitted September 22, 2026 at 03:16PM by mrigaki
via reddit https://ift.tt/I6kRGyN
cybersecurity.bsy.fel.cvut.cz
Introduction to Security
Introduction to Security Class (BSY), FEL, Czech Technical University
Android 17 enables certificate transparency, and breaks custom CAs
https://ift.tt/SNPcF1n
Submitted September 23, 2026 at 05:56PM by ScottContini
via reddit https://ift.tt/9izIsOZ
https://ift.tt/SNPcF1n
Submitted September 23, 2026 at 05:56PM by ScottContini
via reddit https://ift.tt/9izIsOZ
Httptoolkit
Android 17 enables certificate transparency, and breaks custom CAs
Do you want to know what your phone is sending & receiving? Nowadays, that means you need to control who it trusts. In modern connections everything sent &...
Inside Corp MDM, the Android spyware targeting logistics companies
https://ift.tt/pLsq2PN
Submitted September 23, 2026 at 07:24PM by JDBHub
via reddit https://ift.tt/Wfu0pgy
https://ift.tt/pLsq2PN
Submitted September 23, 2026 at 07:24PM by JDBHub
via reddit https://ift.tt/Wfu0pgy
Have I Been Squatted
Inside Corp MDM, the Android spyware targeting logistics companies - Have I Been Squatted
Source-code analysis of the Corp MDM Android spyware campaign targeting logistics companies through fake Google Play pages, with SMS theft, call forwarding, persistence, C2, and detection details.
Breaking the Superuser Guardrails of managed-PostgreSQL Providers
https://ift.tt/1YW7QpU
Submitted September 24, 2026 at 01:26AM by wtfse
via reddit https://ift.tt/mD6qlkj
https://ift.tt/1YW7QpU
Submitted September 24, 2026 at 01:26AM by wtfse
via reddit https://ift.tt/mD6qlkj
Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
Part 2/6 | Breaking the Postgres Superuser Guardrails: Attacking Security-Hardening Extensions |Systemic Risks in the Managed PostgreSQL…
It’s been a month since I published the first part of this research, and interest from the Postgres community has been higher than I expected. Most vendors I contacted were shy to respond, so the Databricks team’s blog post Collaboration makes us all stronger…
I asked my AI agent to inspect a website. The website took over my machine (34-run measurement across 5 agent harnesses)
https://ift.tt/XTw17NA
Submitted September 24, 2026 at 01:26AM by DaimoNNN
via reddit https://ift.tt/4xmaZTM
https://ift.tt/XTw17NA
Submitted September 24, 2026 at 01:26AM by DaimoNNN
via reddit https://ift.tt/4xmaZTM
Efe Çakıcı
I asked my AI agent to inspect a website. The website took over my machine.
A local lab, 34 recorded runs, and 6 stolen credential files. You tell an agent to check a library's docs; the website steals your session and executes commands before the model speaks.
September 23 | 24h Recap: Ubuntu container escape, F5 OAuth RCE and Windows process injection
https://ift.tt/cUkfyzt
Submitted September 24, 2026 at 02:59AM by FishingTechnical453
via reddit https://ift.tt/pJXwAzF
https://ift.tt/cUkfyzt
Submitted September 24, 2026 at 02:59AM by FishingTechnical453
via reddit https://ift.tt/pJXwAzF
Cyberrecaps
Daily Cybersecurity News – September 23, 2026
Ubuntu Linux Use-After-Free Enables Host-Root Container Escape · Chinese UTA0565 Uses Chrome-Windows Zero-Days for CLEANGULP · Process Parameter Poisoning EDR Evasion Technique
Loopjacking: Hijacking Human-in-the-Loop Approval
https://ift.tt/g6kr7OU
Submitted September 24, 2026 at 03:55AM by adithyanak
via reddit https://ift.tt/bn2WJAm
https://ift.tt/g6kr7OU
Submitted September 24, 2026 at 03:55AM by adithyanak
via reddit https://ift.tt/bn2WJAm
arXiv.org
Loopjacking: Hijacking Human-in-the-Loop Approval
Human approval is often treated as the last security boundary before an agent executes a consequential operation. That boundary is only meaningful if the operation presented for review is the...
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs
https://ift.tt/wtuDVpv
Submitted September 24, 2026 at 04:50AM by dx7r__
via reddit https://ift.tt/C6Lrjkx
https://ift.tt/wtuDVpv
Submitted September 24, 2026 at 04:50AM by dx7r__
via reddit https://ift.tt/C6Lrjkx
watchTowr Labs
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry.
We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find…
We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find…
HIRING: AIKOCorp | Full-stack Engineer | Remote
https://ift.tt/qfna3Ig
Submitted September 24, 2026 at 11:17AM by Coolestusername_ever
via reddit https://ift.tt/v2e7rnV
https://ift.tt/qfna3Ig
Submitted September 24, 2026 at 11:17AM by Coolestusername_ever
via reddit https://ift.tt/v2e7rnV
Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee
https://ift.tt/dYFySP3
Submitted September 24, 2026 at 11:34AM by ezzzzz
via reddit https://ift.tt/pUlhwbu
https://ift.tt/dYFySP3
Submitted September 24, 2026 at 11:34AM by ezzzzz
via reddit https://ift.tt/pUlhwbu
Research Blog | Project Black
Bypassing EDR with Local AI
How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard.
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL
https://ift.tt/AV1BnZ7
Submitted September 24, 2026 at 04:32PM by nns_ee
via reddit https://ift.tt/B6gYv1u
https://ift.tt/AV1BnZ7
Submitted September 24, 2026 at 04:32PM by nns_ee
via reddit https://ift.tt/B6gYv1u
nns.ee
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL | nns.ee
Chaining an AtlasService binder command injection and an olc2 HAL binder method into uid 0 with all Linux capabilities from a plain installable app on OxygenOS 16.
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
https://ift.tt/fB1r4k6
Submitted September 24, 2026 at 08:37PM by natcoba
via reddit https://ift.tt/lC1UY52
https://ift.tt/fB1r4k6
Submitted September 24, 2026 at 08:37PM by natcoba
via reddit https://ift.tt/lC1UY52
Cloudflare Blog
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we investigated it, and the steps we took to remediate it.
One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts
https://ift.tt/vpou0O9
Submitted September 24, 2026 at 09:15PM by nibblesec
via reddit https://ift.tt/syLYUa7
https://ift.tt/vpou0O9
Submitted September 24, 2026 at 09:15PM by nibblesec
via reddit https://ift.tt/syLYUa7
Doyensec
One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts
While testing deep links in Chrome for iOS, we noticed a small but important difference. Opening a third-party app through a custom URL scheme normally produced a confirmation prompt. Shortcuts were an exception. As they’re handled by a native Apple app,…